Aave Faces Potential Losses of Up to $230 Million Following Kelp DAO Bridge Exploit
A devastating bridge exploit targeting Kelp DAO has put lending protocol Aave at risk of incurring losses of up to $230 million, contingent upon the outcome of the situation. According to a report published by Aave Labs and LlamaRisk on the Aave governance forum, the incident revolves around rsETH, a liquid restaking token issued by KelpDAO. The protocol utilizes a bridge mechanism to transfer rsETH between blockchains, which locks tokens on one chain and issues corresponding tokens on another. However, an attacker exploited this setup by creating a forged transfer message that appeared legitimate, resulting in the system approving the transfer despite the tokens never leaving the sending chain. This led to the creation of new tokens without backing, with 116,500 rsETH being released from the Ethereum-side bridge. Instead of selling the assets on the open market, the attacker deposited 89,567 rsETH into Aave as collateral and borrowed approximately $190 million in ETH and related assets across Ethereum and Arbitrum. This has left Aave vulnerable to collateral with potentially significant impairment. Aave Labs promptly responded to contain the risk by freezing rsETH markets, setting loan-to-value ratios to zero, and halting new borrowing against the asset. The outcome now largely depends on Kelp's handling of the shortfall. If losses are distributed across all rsETH holders, the token may experience an estimated 15% depegging, resulting in around $124 million in bad debt for Aave. However, if losses are confined to Layer 2 networks, the impact would be more severe, with bad debt increasing to approximately $230 million, primarily affecting networks such as Arbitrum and Mantle. The exploit was made possible by weaknesses in Kelp's verification process for cross-chain messages using LayerZero. By manipulating this process, the attacker was able to make certain assets appear fully backed when they were not, allowing them to extract value from the system. Although LayerZero itself was not directly hacked, its messaging layer exposed flawed assumptions in Kelp's validation of cross-chain data. The incident has raised concerns about the potential for mispriced or undercollateralized loans on Aave, prompting users to reduce their exposure. Approximately $6 billion in total value locked was withdrawn from Aave following the incident, reflecting a broad pullback as participants reacted to the uncertainty. The episode has highlighted Aave's indirect exposure to external systems, with the impact felt through increased collateral risk, pressure on lending positions, and a sharp decline in deposits as users reassessed the safety of interconnected DeFi infrastructure. The report noted that the DAO treasury holds around $181 million in assets and that discussions are underway with ecosystem participants to address potential losses. However, Kelp has yet to outline its plan for allocating losses, leaving Aave's ultimate exposure uncertain as the situation continues to unfold.